PT-2026-52546 · Newsblur · Newsblur

·

CVE-2026-56772

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NewsBlur versions prior to 14.5.0
Description Broken access control allows authenticated users to read private notification feeds. By supplying arbitrary user id values to the 'GET /social/interactions' endpoint, an attacker can bypass ownership verification to access another user's follows, replies, and social activity through enumeration of user id values.
Recommendations Update to version 14.5.0 or later. Avoid using the user id parameter in the 'GET /social/interactions' endpoint to access data not owned by the authenticated user.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56772

Affected Products

Newsblur